Courseiva
Free · No account needed · No credit card

CompTIA SecurityX (CAS-005) Practice Test

973 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 165 min

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

A security architect is designing a microservices application that uses JWTs for authentication. Which of the following is the most critical security concern regarding JWT handling?

AToken expiration not being enforced
BThe JWT being transmitted over HTTP instead of HTTPS
The server not validating the JWT's 'alg' header properlyCorrect
DThe JWT containing personally identifiable information (PII)

A failure to validate the JWT's 'alg' header can allow an attacker to change the algorithm to 'none' or from an asymmetric algorithm (e.g., RS256) to a symmetric one (e.g., HS256), potentially bypassing signature verification. This vulnerability, known as a JWT algorithm confusio…Read full explanation

A healthcare organization is planning to migrate patient data to a cloud provider. The risk assessment identifies that the provider's SOC 2 report does not cover HIPAA controls. What is the BEST course of action?

ARequest the provider's most recent SOC 3 report
BAccept the risk and proceed with migration
Require the provider to sign a Business Associate Agreement (BAA)Correct
DRequire the provider to encrypt all data at rest and in transit

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. A SOC 2 report that does not cover HIPAA controls does not satisfy the requirement; the B…Read full explanation

Based on the exhibit, what vulnerability is present in the firewall rule?

Overly permissive service specificationCorrect
BSource IP range is too broad
CNo logging is enabled
DMissing application ID control

The firewall rule permits 'any' as the service, meaning all TCP/UDP ports and protocols are allowed through. This is overly permissive because it bypasses the principle of least privilege, exposing the internal network to unnecessary traffic and potential attacks. A proper rule s…Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All CAS-005 questionsCAS-005 exam guideStudy guidePractice by domain